From owner-freebsd-security@FreeBSD.ORG Tue Mar 3 00:32:57 2009 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 740531065673 for ; Tue, 3 Mar 2009 00:32:57 +0000 (UTC) (envelope-from healey.rich@itreign.com) Received: from mail.psych0tik.net (115-69-7-62.dyn.comcen.net.au [115.69.7.62]) by mx1.freebsd.org (Postfix) with ESMTP id EE25E8FC16 for ; Tue, 3 Mar 2009 00:32:56 +0000 (UTC) (envelope-from healey.rich@itreign.com) Received: from XeniaVista (CPE-61-9-142-180.static.vic.bigpond.net.au [61.9.142.180]) by mail.psych0tik.net (Postfix) with ESMTPA id D439315EC12 for ; Tue, 3 Mar 2009 11:32:54 +1100 (EST) From: "Rich Healey" To: References: <20090302021415.GU5602@noncombatant.org> In-Reply-To: <20090302021415.GU5602@noncombatant.org> Date: Tue, 3 Mar 2009 11:32:51 +1100 Message-ID: <004201c99b97$977935c0$c66ba140$@rich@itreign.com> MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit X-Mailer: Microsoft Office Outlook 12.0 Thread-Index: Acma30hpgxe4/jqcQSGjBgPp5bJaOwAuDkyQ Content-Language: en-au X-Mailman-Approved-At: Tue, 03 Mar 2009 00:55:33 +0000 Subject: RE: OPIE considered insecure X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 03 Mar 2009 00:32:57 -0000 -----Original Message----- From: owner-freebsd-security@freebsd.org [mailto:owner-freebsd-security@freebsd.org] On Behalf Of Chris Palmer Sent: Monday, 2 March 2009 1:14 PM To: freebsd-security@freebsd.org Subject: Re: OPIE considered insecure Rich Healey writes: > I'm thinking about implementing OPIE, but after reading this I'm not so > sure. What's consensus on the best approach to one time logins? Why are people logging into their remote servers from assumed-untrustworthy clients at all? _______________ Because a truly secure machine (ie one that's switched off) isn't much use to me.